Hive0131 is a financially motivated threat actor likely originating from South America, first observed in May 2025. This group routinely conducts email campaigns, primarily in Latin America, to deliver a wide array of commodity malware. What distinguishes Hive0131 is their consistent imitation of official government correspondence, such as fake notifications of criminal proceedings from entities like The Judiciary of Colombia, as a primary tactic for initial access. Their operations focus on financial theft and digital extortion, targeting financial institutions, cryptocurrency platforms, and fintech sectors.